Posting Date: 2026/09/07

【Vulnerability Alert】2 Critical Security Vulnerabilities Found in SonicWall NSM On-Prem

  • Subject: 【Vulnerability Alert】2 Critical Security Vulnerabilities Found in SonicWall NSM On-Prem


  • Description:
    • Forwarded security alert TWCERTCC-200-202609-00000002 from Taiwan Computer Emergency Response Team/Coordination Center (TWCERT/CC).
    • SonicWall has issued a advisory regarding critical security vulnerabilities in NSM On-Prem (CVE-2026-78327, CVSS: 9.1 and CVE-2026-81939, CVSS: 9.1). CVE-2026-81939 is a Zip Slip vulnerability residing in the file upload and archive handling functionality of NSM On-Prem, allowing attackers to extract files outside the intended target directory using crafted files. CVE-2026-78327 is an OS Command Injection vulnerability that allows authenticated attackers with SuperAdmin privileges to execute arbitrary commands on the underlying host, resulting in remote code execution.
  • Affected Platforms:
    • Network Security Manager (NSM) On-Prem version 4.3.0 and prior versions
  • Recommendations:
    • Please update to the following version: Network Security Manager (NSM) On-Prem version 4.3.1-R4 and subsequent versions
  • References:

Computer and Communication Center
Network System Division